CVE-2026-63078Active Exploitation

MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

4.0/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-05); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-05: 1Mentions · 2026-08-09: 1Mentions · 2026-08-10: 1Active Exploitation · 2026-08-09: 1Active Exploitation · 2026-08-10: 1Patch / Workaround · 2026-08-10: 1Technical Details · 2026-08-09: 1Technical Details · 2026-08-10: 108-0508-0908-10
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Referenced assets32 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-051
General1
2026-08-091
Active Exploitation1
2026-08-101
Active Exploitation1
Full discourse3 posts
  • PortSwigger@PortSwigger
    General

    ☠️ AI can do original security research, not just pattern-match known bugs ☠️ It found a genuine 0-day (now CVE-2026-63078) ☠️Its biggest discovery, "Shared-Parser Confusion," only surfaced once a human stepped back in. AI took it 90% of the way; human judgment found the rest

    Post summary

    The message announces a newly identified 0‑day (CVE‑2026‑63078) dubbed "Shared‑Parser Confusion," but offers no proof of concept, exploit details, or mitigation guidance.

    100511.1K
    110.1K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:週末のセキュリティ関連ニュース/記事】 <脆弱性> ・WordPressに新たな認証不要XSS PHPのコード実行につながる恐れ - 早急にパッチを(CVE-2026-64638) https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html ・負荷分散ソリューション「Progress Kemp LoadMaster」の欠陥がKEVに追加される 悪用の報告多数(CVE-2026-8037) https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-cisa.html ・Metabaseのゼロデイ脆弱性が悪用される 認証なしで管理者アクセスが可能に https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html ・Chrome151で複数の重大な脆弱性を修正 https://www.securityweek.com/critical-vulnerabilities-patched-with-chrome-151-update/ ・LinuxのSCTPネットワークコードに18年来の脆弱性、ローカルユーザーのroot権限取得やコンテナエスケープが可能に(CVE-2026-64564) https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html ・AI支援型ツールのHTTP Terminator、新たなHTTP非同期手法とApacheゼロデイを発見(CVE-2026-63078) https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html <マルウェア・その他脅威> ・有害なnpmパッケージ約800件がクロスプラットフォームRATとインフォスティーラーを配布 https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html ・ClickFix攻撃で暗号通貨ウォレット内の一部盗むmacOS用スティーラーが配布される https://thehackernews.com/2026/08/clickfix-attacks-deliver-macos-stealer.html ・Head Mareグループがビデオ会議ツール「TrueConf」を侵害 インストーラーにバックドアを仕掛ける https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/ ・新マルウェア「Vanta Stealer」 標的はゲーマー・暗号資産ユーザー・Webアプリ https://hackread.com/vanta-stealer-malware-gamers-crypto-users-web-apps/ <ランサムウェア> ・複数ランサムウェアグループがCEOでなく40代管理職を標的に https://www.theregister.com/security/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/5284499 ・ランサムウェア攻撃が世界的に急増中 https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934 <データ侵害/サイバー犯罪> ・ビッシング使う恐喝グループUNC6671が名称変更 被害額はこれまでに1,000万ドル超 https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/ ・米医療ソフトウェア会社Unlimited Technology Systemsのデータ侵害、380万人超に影響 https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/ ・リーバイ・ストラウスがデータ侵害を公表 従業員へのソーシャルエンジニアリング攻撃で https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/ ・米ノースカロライナ港湾局、サイバー攻撃による業務への影響を確認 https://www.bleepingcomputer.com/news/security/north-carolina-ports-confirms-cyberattack-disrupting-operations/ ・仏ラグビークラブのスタッド・フランセ・パリ、サイバー攻撃受けるもシステムを復旧 データ流出の調査は継続 https://therecord.media/french-rugby-club-restores-systems-after-cyberattack ・米防衛関連企業、フィッシング攻撃でMicrosoft 365アカウントに侵入許す https://www.theregister.com/security/2026/08/07/ieh-corp-says-phished-staffer-opened-gates-to-company-m365/5284523 <AI関連> ・Living off the coding agent:トンネルとLaunchAgentsに関する2つのお話 https://www.elastic.co/security-labs/coding-agent-launchagent-tunnel-detection ・アトラシアンの企業向けAIアシスタントRovoBlastに脆弱性 ワンクリックでデータが漏えいする恐れ https://www.varonis.com/blog/rovoblast ・OpenAI、セキュリティ上の懸念からAstraモデルの開発を遅らせると発表 https://techcrunch.com/2026/08/07/openai-says-it-slowed-astra-model-development-over-security-concerns/ ・AI生成したパッチの約半分は失敗作 https://www.darkreading.com/application-security/ai-generated-patches-fail-half-time ・中国AIモデル「Kimi」がサイバーセキュリティテスト環境から脱出 研究者が報告 https://techcrunch.com/2026/08/07/chinese-ai-model-kimi-escaped-its-cybersecurity-testing-environment-researchers-say/ <サイバー戦/APT/国家型アクター/地政学関連> ・「水道システム管理者はインターネットを使うべきでない」と元NSA長官が発言 イラン関与が疑われる攻撃受け https://www.theregister.com/security/2026/08/07/water-system-controllers-dont-belong-on-the-internet-says-ex-nsa-chief-after-suspected-iran-attacks/5285070 <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・米ニューメキシコ州裁判所、子どもに悪影響を与えたとしてメタに5億6,700万ドルの支払いを命じる https://therecord.media/new-mexico-judge-orders-meta-567-million-kids-safety <プライバシー> ・アンソロピック、OpenAI、Cursorなどにセキュリティとプライバシーの徹底を開発者が呼びかけ https://www.theregister.com/ai-and-ml/2026/08/08/devs-to-anthropic-openai-cursor-and-friends-make-security-and-privacy-the-default/5285107 <リサーチ/攻撃手法/TTP> ・LockBit 5.0のLinux用マルウェアを分析 ChaCha20とCurve25519使ったオフラインでの暗号化、strace回避およびIoCを解説 https://netacoding.com/posts/lockbit5-analysis/ ・多段階型PowerShellローダーについて調査 https://malwr-analysis.com/2026/08/08/investigating-a-multi-stage-powershell-loader/ ・一度書き込めばどこでもシェルが使用可能 任意のファイル書き込みからリモートでコードを実行できるように https://ethiack.com/info-hub/research/write-once-shell-everywhere-arbitrary-file-writes-into-rce ・ポーランドの研究者らが自国のWebサイトを調査 裁判所や病院、空港などがハッキング被害の恐れありと判明 https://techcrunch.com/2026/08/07/security-researchers-scanned-the-polish-web-and-found-courts-hospitals-and-airports-at-risk-of-hacks/ ・監視カメラによる人物の特定を防ぐ「防御」パターンを研究者が発見 https://techcrunch.com/2026/08/09/this-adversarial-pattern-can-prevent-surveillance-cameras-from-detecting-you/ ・新たなCSS攻撃、Webメールの防御策を破ってパスワードとトークンを盗む https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html

    Post summary

    Multiple CVEs are reported as currently being exploited in the wild, with patches or mitigations already released for some, highlighting an active threat landscape.

    000101.3K
    1.3K followersView on X
  • Sandeep Alluru@sandeep_alluru
    Active Exploitation

    An AI invented a new web attack — then accidentally stole a bank’s API key with it. PortSwigger pointed it at 30,000 live sites. > ~700 came back vulnerable > Airport flight + passenger panels exposed > Apache 0-day: CVE-2026-63078 Novel research, or just fast fuzzing? https://t.co/k1EiWTWHlB

    Post summary

    The tweet reports an AI‑generated web attack that uncovered a new Apache 0‑day (CVE-2026-63078), identifying around 700 vulnerable live sites and exposing airline passenger panels.

    0000041
    60 followersView on X

Explore more